Your employees are probably already using artificial intelligence.

They may be drafting emails with ChatGPT, summarizing meetings with an AI assistant, using Microsoft Copilot, generating marketing material, screening job applicants, or relying on AI features built into software the company already owns.

The first governance question is not whether the business has an advanced AI program. It is whether anyone knows which AI systems are being used, what information is going into them, and who is responsible when something goes wrong.

ISO/IEC 42001 provides a management-system framework for answering those questions. It contains 38 reference controls in Annex A, covering areas such as policy, accountability, resources, impact assessment, the AI system life cycle, data, communication, responsible use, and suppliers.

A small business does not need to tackle all of that at once. It does need to start deliberately.

There is no universal ISO 42001 minimum

ISO 42001 does not say that every organization must implement the same short list of controls. The appropriate controls depend on the organization’s AI systems, risks, objectives, contractual obligations, and legal requirements.

The standard expects an organization to assess its AI risks, determine which controls are necessary, compare those decisions against Annex A, and document why controls are included or excluded in a Statement of Applicability.

That means the controls below are a practical starting point, not a certification checklist. A company using an AI assistant to improve internal emails has a different risk profile from one using AI to make employment decisions, diagnose patients, approve loans, operate machinery, or provide an AI product to customers.

A practical starter set for an SMB

For many small and medium-sized businesses that use third-party AI tools, these 15 controls provide a reasonable foundation.

1. Establish an AI policy — A.2.2

Create a short policy that explains:

  • Which AI tools are approved
  • What information employees may and may not enter
  • When a person must review AI-generated work
  • Which uses are prohibited or require approval
  • How employees report a concern or incident

The policy should be specific enough to guide a real decision. “Use AI responsibly” is not enough.

2. Align AI with existing policies — A.2.3

AI does not sit outside the rest of the business. Connect the AI policy to existing requirements for privacy, cybersecurity, acceptable use, records retention, human resources, intellectual property, procurement, and vendor management.

If employees cannot put customer information into an unapproved file-sharing service, they should not put it into an unapproved AI service either.

3. Review the AI policy — A.2.4

Review the policy at least annually and when the business adopts a significant new AI system, changes how an existing system is used, experiences an incident, or learns about a material new risk.

4. Assign ownership — A.3.2

Name one person who is accountable for coordinating AI governance. That does not have to be a full-time AI officer.

The business should still document who approves AI tools, who evaluates risk, who manages vendors, who handles incidents, and who can accept residual risk on behalf of leadership.

5. Make concerns easy to report — A.3.3

Give employees, customers, and other affected people a clear way to report inaccurate, harmful, biased, insecure, or unexpected AI behavior. The process can be simple, but someone must own the response.

6. Maintain an AI inventory — A.4.2

Keep a list of AI systems the company develops, purchases, or uses. At a minimum, record:

  • System and vendor
  • Business purpose
  • Internal owner
  • Users or affected parties
  • Information used by the system
  • Important integrations
  • Whether the use could materially affect a person or the business

An organization cannot manage AI systems it does not know it has.

7. Document the data involved — A.4.3

Identify whether each AI system receives customer data, employee data, personal information, confidential business information, intellectual property, regulated records, or public information.

Also determine whether the vendor stores prompts, uses submitted information to improve its models, or allows the business to control retention and training.

8. Train employees — A.4.6

Training should cover the decisions employees make every day:

  • Use only approved tools
  • Do not submit restricted information without authorization
  • Check facts, calculations, citations, and code
  • Recognize bias and unreliable output
  • Know when human review is mandatory
  • Report incidents and unexpected results

9. Create an AI impact-assessment process — A.5.2

Before approving a higher-risk use, ask what could happen to the business, customers, employees, or the public if the AI system is wrong, unfair, unavailable, manipulated, or used outside its intended purpose.

The depth of the assessment should match the risk. A low-risk writing assistant may need a short review. An employment, safety, financial, healthcare, or customer-eligibility system requires much more scrutiny.

10. Keep assessment records — A.5.3

Document the assessment, decision, required safeguards, approver, and next review date. A decision that exists only in someone’s memory is difficult to manage, defend, or improve.

11. Set expectations for data quality — A.7.4

If AI output supports an important decision, make sure the underlying data is accurate, relevant, sufficiently complete, and appropriate for the intended use. Poor or outdated data can produce confident-looking answers that are still wrong.

12. Provide a way to report external impacts — A.8.3

If customers or other outside parties interact with or are affected by an AI system, tell them how to report a problem. Do not require them to understand the technology before the business will listen.

13. Plan AI incident communication — A.8.4

Decide who must be notified when an AI incident affects customers, employees, vendors, regulators, insurers, or business partners. Connect this process to the existing incident-response plan instead of creating a separate process that nobody remembers.

14. Define responsible-use procedures — A.9.2

Turn the AI policy into repeatable steps. Define which uses require approval, how output is reviewed, what testing is expected, when activity should be logged, and when a system must be suspended.

Human review should be meaningful. A person who lacks the information, authority, or time to challenge an AI result is not an effective control.

15. Review AI suppliers — A.10.3

Ask AI vendors about security, privacy, data retention, model training, subcontractors, availability, incident notification, audit rights, and deletion of company information.

The contract should support the promises the business makes to its customers and employees. A familiar vendor name does not remove the company’s responsibility to understand how the service is used.

What should a small business do first?

Do not begin by writing a large policy that nobody will use. Start with a few concrete actions:

  1. Name an accountable owner.
  2. Inventory the AI tools already in use.
  3. Identify which tools receive sensitive information or influence important decisions.
  4. Publish basic employee rules for approved tools, restricted data, verification, and reporting.
  5. Review the highest-risk systems and vendors first.
  6. Record the decisions, safeguards, owners, and review dates.

This creates enough visibility to decide where a deeper risk assessment is needed.

When the starter set is not enough

An organization will likely need additional Annex A controls when it:

  • Develops, fine-tunes, or substantially modifies an AI system
  • Uses AI for employment, credit, healthcare, insurance, education, safety, legal, or eligibility decisions
  • Processes sensitive, regulated, or high-volume personal information
  • Provides an AI-enabled product or service to customers
  • Uses automated systems with limited human oversight
  • Depends on AI for critical operations
  • Operates in a jurisdiction or industry with additional AI requirements

Those situations can require deeper impact assessments, data provenance, testing and validation, deployment controls, technical documentation, event logging, ongoing monitoring, customer information, and clearly allocated responsibilities across the AI supply chain.

This is the beginning, not the risk-management program

A policy, inventory, and vendor checklist are useful. They are not a complete AI management system, and they do not demonstrate ISO/IEC 42001 conformity by themselves.

Good AI risk management is an ongoing cycle: understand the context, identify risks, select and implement controls, assign accountability, monitor results, investigate incidents, and improve the program as the technology and business change.

The goal is not to collect paperwork. It is to make better decisions about where AI belongs in the business, what could go wrong, and what the organization will do about it.

Minnesota Risk & Cybersecurity Advisory can help your organization inventory its AI use, evaluate the risks that matter, and build a practical governance roadmap without treating a small business like a global technology company.

This article provides general educational information and is not legal advice, certification advice, or a substitute for an organization-specific risk assessment.